CRITICAL
CVE-2024-55956
CVSS
9.8
KEV
Description
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.
Summary dbcve.org
Cleo Harmony, VLTrader, and LexiCom before version 5.8.0.24 contain a critical vulnerability allowing unauthenticated users to execute arbitrary Bash or PowerShell commands on the host system through the Autorun directory feature, which uses insecure default settings.
Mitigation
Upgrade to version 5.8.0.24 or later and review/restrict the Autorun directory configuration to prevent unauthorized command execution.
Weakness (CWE)
CWE-77
Command Injection
EPSS Score
93.97%
Probability of exploitation in next 30 days
99.8th percentile
References
https://support.cleo.com/hc/en-us/articles/28408134019735-Cleo-Product-Security-Advisory-CVE-Pending
Vendor Advisory
https://support.cleo.com/hc/en-us/articles/28408134019735-Cleo-Product-Security-Update
Vendor Advisory
https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild
Exploit, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-55956
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.